Latest CVE Feed
-
4.0
MEDIUMCVE-2010-3475
IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statemen... Read more
Affected Products : db2- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-2086
Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expres... Read more
Affected Products : myfaces- Published: May. 27, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-4300
Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, C... Read more
Affected Products : database_server- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2009-1873
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the logfile parameter.... Read more
Affected Products : jrun- Published: Aug. 18, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2010-4242
The hci_uart_tty_open function in the HCI UART driver (drivers/bluetooth/hci_ldisc.c) in the Linux kernel 2.6.36, and possibly other versions, does not verify whether the tty has a write operation, which allows local users to cause a denial of service (NU... Read more
Affected Products : linux_kernel- Published: Jan. 11, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-1617
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.... Read more
Affected Products : moodle- Published: Apr. 29, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-2638
Unspecified vulnerability in IBM WebSphere MQ 7.0 before 7.0.1.5 allows remote authenticated users to cause a denial of service (disk consumption) via vectors that trigger an FDC with an RM680004 Probe Id value.... Read more
Affected Products : websphere_mq- Published: Nov. 15, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-1560
Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.... Read more
Affected Products : db2- Published: Apr. 27, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-3528
Unspecified vulnerability in the PeopleSoft Enterprise CRM - Common Components component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #41, 9.0 Bundle #28, and 9.1 Bundle #4 allows remote authenticated users to affect confidentiality via unknown vec... Read more
Affected Products : peoplesoft_and_jdedwards_product_suite- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-3589
Unspecified vulnerability in the Oracle Application Object Library component in Oracle Applications 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related t... Read more
Affected Products : e-business_suite- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-5141
Format string vulnerability in War FTP Daemon (warftpd) 1.82 RC 12 allows remote authenticated users to cause a denial of service (crash) via format string specifiers in a LIST command.... Read more
Affected Products : warftpd- Published: Apr. 01, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-0102
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0087 and CVE-2012-0101.... Read more
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-3840
The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a craft... Read more
- Published: Jan. 14, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2021-39879
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication... Read more
Affected Products : gitlab- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2010-4011
Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own m... Read more
Affected Products : mac_os_x_server- Published: Nov. 17, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2024-12292
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, where sensitive information passed in GraphQL mutations may have been retained i... Read more
Affected Products : gitlab- Published: Dec. 12, 2024
- Modified: Jul. 11, 2025
-
4.0
MEDIUMCVE-2010-2634
RSA enVision before 3.7 SP1 allows remote authenticated users to cause a denial of service via unspecified vectors.... Read more
Affected Products : envision- Published: Aug. 10, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2020-14847
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via ... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2013-2506
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.... Read more
Affected Products : spree- Published: Mar. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-1907
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4 before 8.1.4.7 allows remote authenticated users to read cookies via unspecified vectors.... Read more
Affected Products : rational_license_key_server- Published: May. 08, 2015
- Modified: Apr. 12, 2025